ID

VAR-202512-4489


CVE

CVE-2025-64153


DESCRIPTION

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.6.0 through 7.6.3, FortiExtender 7.4.0 through 7.4.7, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated attacker to execute unauthorized code or commands via a specific HTTP request.

Trust: 1.0

sources: NVD: CVE-2025-64153

AFFECTED PRODUCTS

vendor:fortinetmodel:fortiextenderscope:gteversion:7.4.0

Trust: 1.0

vendor:fortinetmodel:fortiextenderscope:lteversion:7.6.3

Trust: 1.0

vendor:fortinetmodel:fortiextenderscope:lteversion:7.4.7

Trust: 1.0

vendor:fortinetmodel:fortiextenderscope:gteversion:7.6.0

Trust: 1.0

vendor:fortinetmodel:fortiextenderscope:lteversion:7.2.5

Trust: 1.0

vendor:fortinetmodel:fortiextenderscope:gteversion:7.0.0

Trust: 1.0

vendor:fortinetmodel:fortiextenderscope:lteversion:7.0.4

Trust: 1.0

vendor:fortinetmodel:fortiextenderscope:gteversion:7.2.0

Trust: 1.0

sources: NVD: CVE-2025-64153

CVSS

SEVERITY

CVSSV2

CVSSV3

psirt@fortinet.com: CVE-2025-64153
value: HIGH

Trust: 1.0

nvd@nist.gov: CVE-2025-64153
value: HIGH

Trust: 1.0

psirt@fortinet.com: CVE-2025-64153
baseSeverity: HIGH
baseScore: 7.2
vectorString: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.2
impactScore: 5.9
version: 3.1

Trust: 2.0

sources: NVD: CVE-2025-64153 // NVD: CVE-2025-64153

PROBLEMTYPE DATA

problemtype:CWE-78

Trust: 1.0

sources: NVD: CVE-2025-64153

EXTERNAL IDS

db:NVDid:CVE-2025-64153

Trust: 1.0

sources: NVD: CVE-2025-64153

REFERENCES

url:https://fortiguard.fortinet.com/psirt/fg-ir-25-739

Trust: 1.0

sources: NVD: CVE-2025-64153

SOURCES

db:NVDid:CVE-2025-64153

LAST UPDATE DATE

2026-01-15T23:26:36.659000+00:00


SOURCES UPDATE DATE

db:NVDid:CVE-2025-64153date:2025-12-09T21:25:28.153

SOURCES RELEASE DATE

db:NVDid:CVE-2025-64153date:2025-12-09T18:16:04.910